Firefox PDF.js Privileged Javascript Injection

Discussion in 'News Aggregator' started by Packet Storm, 24 Aug 2015.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module gains remote code execution on Firefox 35-36 by abusing a privilege escalation bug in resource:// URIs. PDF.js is used to exploit the bug. This exploit requires the user to click anywhere on the page to trigger the vulnerability.

    Continue reading...
     

Share This Page

Loading...